Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 635

Количество 367 635

github логотип

GHSA-45vh-fhgx-cr2p

больше 4 лет назад

x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement paravirtualisation, Xen's novel approach to virtualization. In AMD64, Xen had to use a different implementation approach, so Xen does not use ring 1 to support 64-bit guests. With the focus now being on 64-bit systems, and the availability of explicit hardware support for virtualization, fixing speculation issues in ring 1 is not a priority for processor companies. Indirect Branch Restricted Speculation (IBRS) is an architectural x86 extension put together to combat speculative execution sidechannel attacks, including Spectre v2. It was retrofitted in microcode to existing CPUs. For more details on Spectre v2, see: http://xenbits.xen.org/xsa/advisory-254.html However, IBRS does not architecturally protect ring 0 from predictions learnt ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-45vg-h4f5-372w

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raptive Raptive Ads allows Reflected XSS. This issue affects Raptive Ads: from n/a through 3.7.3.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-45vg-36w4-jh4r

больше 4 лет назад

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

EPSS: Низкий
github логотип

GHSA-45vg-2v73-vm62

почти 8 лет назад

Moderate severity vulnerability that affects org.springframework:spring-core

EPSS: Низкий
github логотип

GHSA-45vf-xfc8-r7cc

больше 4 лет назад

The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45vf-ccx3-9p8v

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.

EPSS: Низкий
github логотип

GHSA-45vc-v954-j6hx

больше 4 лет назад

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-45vc-mrxr-qgr2

больше 4 лет назад

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-45vc-8wxf-vrvf

почти 4 года назад

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occur in /cgi-bin/R14.2/log.pl via the cmd HTTP GET parameter and /cgi-bin/R14.2/checkping.pl via the addr HTTP GET parameter. This allows authenticated users to execute commands on the operating system.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-45vc-784v-vp78

12 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow When an invalid stc_type is provided, the function allocates memory for shared_stc but jumps to unlock_and_out without freeing it, causing a memory leak. Fix by jumping to free_shared_stc label instead to ensure proper cleanup.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-45v9-xmmj-rxgq

5 месяцев назад

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-45v9-w9fh-33j6

больше 1 года назад

Mattermost fails to properly validate post props

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-45v9-p764-4x3m

7 месяцев назад

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in '/add_exclude_dir?sid=', affecting the 'exclude_dir' parameter.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-45v8-qc9w-mcmj

4 месяца назад

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-45v7-mh84-5f9p

около 4 лет назад

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-45v7-gg96-grpr

больше 4 лет назад

** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.

EPSS: Низкий
github логотип

GHSA-45v7-65q8-x294

больше 4 лет назад

Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-45v6-w2jm-fwmg

больше 1 года назад

In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.

CVSS3: 1.8
EPSS: Низкий
github логотип

GHSA-45v6-m9r2-hc3m

больше 4 лет назад

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.

EPSS: Низкий
github логотип

GHSA-45v6-jjpf-7xvm

около 1 месяца назад

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-45vh-fhgx-cr2p

x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement paravirtualisation, Xen's novel approach to virtualization. In AMD64, Xen had to use a different implementation approach, so Xen does not use ring 1 to support 64-bit guests. With the focus now being on 64-bit systems, and the availability of explicit hardware support for virtualization, fixing speculation issues in ring 1 is not a priority for processor companies. Indirect Branch Restricted Speculation (IBRS) is an architectural x86 extension put together to combat speculative execution sidechannel attacks, including Spectre v2. It was retrofitted in microcode to existing CPUs. For more details on Spectre v2, see: http://xenbits.xen.org/xsa/advisory-254.html However, IBRS does not architecturally protect ring 0 from predictions learnt ...

CVSS3: 5.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-45vg-h4f5-372w

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Raptive Raptive Ads allows Reflected XSS. This issue affects Raptive Ads: from n/a through 3.7.3.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-45vg-36w4-jh4r

XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-45vg-2v73-vm62

Moderate severity vulnerability that affects org.springframework:spring-core

2%
Низкий
почти 8 лет назад
github логотип
GHSA-45vf-xfc8-r7cc

The mad_layer_III function in layer3.c in Underbit MAD libmad 0.15.1b allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

CVSS3: 7.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-45vf-ccx3-9p8v

Cross-site scripting (XSS) vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to inject arbitrary web script or HTML via via the message text.

2%
Низкий
больше 4 лет назад
github логотип
GHSA-45vc-v954-j6hx

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0602, CVE-2019-0615, CVE-2019-0616, CVE-2019-0619, CVE-2019-0660.

CVSS3: 6.5
8%
Низкий
больше 4 лет назад
github логотип
GHSA-45vc-mrxr-qgr2

HTMLDOC 1.9.7 allows a stack-based buffer overflow in the hd_strlcpy() function in string.c (when called from render_contents in ps-pdf.cxx) via a crafted HTML document.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45vc-8wxf-vrvf

In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occur in /cgi-bin/R14.2/log.pl via the cmd HTTP GET parameter and /cgi-bin/R14.2/checkping.pl via the addr HTTP GET parameter. This allows authenticated users to execute commands on the operating system.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-45vc-784v-vp78

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, Fix memory leak in hws_action_get_shared_stc_nic error flow When an invalid stc_type is provided, the function allocates memory for shared_stc but jumps to unlock_and_out without freeing it, causing a memory leak. Fix by jumping to free_shared_stc label instead to ensure proper cleanup.

CVSS3: 5.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-45v9-xmmj-rxgq

A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS3: 7.3
0%
Низкий
5 месяцев назад
github логотип
GHSA-45v9-w9fh-33j6

Mattermost fails to properly validate post props

CVSS3: 6.5
1%
Низкий
больше 1 года назад
github логотип
GHSA-45v9-p764-4x3m

Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18 contain a persistent authenticated Cross-Site Scripting (XSS) vulnerability. An attacker could send malicious content to an authenticated user and steal information from their session due to insufficient validation of user input in '/add_exclude_dir?sid=', affecting the 'exclude_dir' parameter.

CVSS3: 5.4
0%
Низкий
7 месяцев назад
github логотип
GHSA-45v8-qc9w-mcmj

A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

CVSS3: 9.8
1%
Низкий
4 месяца назад
github логотип
GHSA-45v7-mh84-5f9p

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVSS3: 9.8
56%
Средний
около 4 лет назад
github логотип
GHSA-45v7-gg96-grpr

** DISPUTED ** QueryString.php in Simple Machines Forum (SMF) 1.0.7 and earlier, and 1.1rc2 and earlier, allows remote attackers to more easily spoof the IP address and evade banning via a modified X-Forwarded-For HTTP header, which is preferred instead of other more reliable sources for the IP address. NOTE: the original researcher claims that the vendor has disputed this issue.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v7-65q8-x294

Stored XSS vulnerability in Jenkins Bitbucket Server Integration Plugin

CVSS3: 5.4
1%
Низкий
больше 4 лет назад
github логотип
GHSA-45v6-w2jm-fwmg

In Archer Platform 6 through 6.14.00202.10024, an authenticated user with record creation privileges can manipulate immutable fields, such as the creation date, by intercepting and modifying a Copy request via a GenericContent/Record.aspx?id= URI. This enables unauthorized modification of system-generated metadata, compromising data integrity and potentially impacting auditing, compliance, and security controls.

CVSS3: 1.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-45v6-m9r2-hc3m

The CGI implementation on Cisco TelePresence endpoint devices with software 1.2.x through 1.5.x allows remote authenticated users to execute arbitrary commands via a malformed request, related to "command injection vulnerabilities," aka Bug ID CSCtb31659.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-45v6-jjpf-7xvm

Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.

CVSS3: 7.1
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу